news.mlab.sh
Back to the feed
vulnerability

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

HighCVSS 8.8
Summary

The U.S. CISA has added three Linux kernel vulnerabilities to its list of exploited flaws, citing active exploitation. These vulnerabilities – CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 – could lead to memory disclosure, denial-of-service, or privilege escalation. Federal agencies are urged to apply patches immediately to mitigate the risk.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are CVE-2025-39682 (CVSS score: 9.8), an improper check for unusual or exceptional conditions vulnerability in the TLS receive path that could allow local authenticated users to trigger memory disclosure or denial-of-service (DoS); CVE-2026-53266 (CVSS score: 8.8), an out-of-bounds write vulnerability in the ebtables Source Network Address Translation (SNAT) Address Resolution Protocol (ARP) rewrite path that could allow a local attacker to trigger unintended system behavior, DoS, or local privilege escalation; and CVE-2025-39964 (CVSS score: 7.8), a race condition vulnerability that could allow concurrent writes to the same AF_ALG socket, allowing a local attacker to crash the system or corrupt cryptographic operation results, causing DoS or data integrity issues. Currently, there are no details on how the three vulnerabilities are being exploited in the wild, and if they are being weaponized as part of a single attack chain. However, Red Hat has updated the advisories for all the flaws as of September 19, 2026, at 2 a.m. UTC to acknowledge active exploitation. "This CVE is high risk and there are known public exploits leveraging this vulnerability," Red Hat said. "Address this vulnerability with high priority." Pursuant to Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by September 21, 2026.

Read the full article at The Hacker News